Skip to content

Conversation

@leifnel
Copy link

@leifnel leifnel commented Feb 6, 2026

This change adds support for a dedicated TSIG key for DNS dynamic updates,
allowing DHCP-DDNS clients (e.g. Kea) to update primary zones without relying
on the RNDC key.

The implementation:

  • introduces a configurable DDNS TSIG key (name / algorithm / secret)
  • allows enabling DDNS updates per primary zone
  • supports multiple grants in update-policy (RNDC + DDNS)
  • does not overwrite update-policy when DDNS is disabled
  • keeps BIND and DDNS clients fully decoupled

This enables secure DDNS setups where the DHCP server and BIND may run on
separate hosts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant